Data Breaches

AT&T confirms data of 73 million customers leaked on Dark Web

0

AT&T confirmed that it has been impacted by a data breach affecting 73 million current and former customers after initially denying the leaked data originated from them.

AT&T has repeatedly denied for the past two weeks that a massive trove of leaked customer data originated from them or that their systems had been breached.

AT&T stated that based on its preliminary analysis, the data set appears to be from 2019 or earlier, impacting approximately 7.6 million current AT&T account holders and approximately 65.4 million former account holders.

In 2021, a threat actor known as Shiny Hunters claimed to be selling the stolen data of 73 million AT&T customers. This data includes names, addresses, phone numbers, and, for many customers, social security numbers and birth dates.

At the time, AT&T denied that they suffered a breach or that the data originated from them.

Now this year, another threat actor leaked the massive dataset on a hacking forum, stating it was the same data stolen by Shiny Hunters.

It was determined that it contained the same sensitive information that ShinyHunters claimed was stolen. However, not every customer had their social security number or birth date exposed by the incident.

AT&T once again denied that they suffered a breach or that the data originated from them.

Since the leak, some of the AT&T and DirectTV customers stated that they used the disposable email feature of Gmail and Yahoo to create DirectTV or AT&T-specific email addresses that were only used when they signed up for their service.

These email addresses were confirmed not to be used on any other platform, indicating that the data had to have originated from DirectTV or AT&T.

Now AT&T said that they would only share further information about the breach in their published statement and a new page on keeping AT&T accounts secure.

The page on keeping accounts secure further discloses that the passcodes for 7.6 million AT&T customers were compromised as part of the breach and have been reset by the company.

Customers use passcodes to further secure their AT&T accounts by requiring them to receive customer support, manage accounts at retail stores, or sign into their online accounts.

The company will notify all 73 million former and current customers about the breach and the next steps they should take.

AT&T customers can also use Have I Been Pwned to determine if their data was compromised in this breach.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Darcula phishing service targets iPhone users via iMessage

Previous article

Jackson County IT systems hit by Ransomware attack

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *